๐Ÿ” CVE Alert

CVE-2026-106105

UNKNOWN 0.0

Quasar Framework: Development TLS private keys are cached with overly permissive filesystem permissions

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/ssl-certificate 2.1.0, @quasar/cli 5.0.4, and @quasar/app-vite 3.3.0, the @quasar/ssl-certificate utility cached a combined private key and certificate PEM without explicitly applying owner-only filesystem permissions. Another local user able to read the cache can copy the key and impersonate a development TLS endpoint in an environment that trusts the certificate. The generated certificate was also CA-capable, carried unnecessarily broad key usages, and encoded the IPv6 loopback address as a DNS subject alternative name. This issue is fixed in @quasar/ssl-certificate 2.1.0, @quasar/cli 5.0.4, and @quasar/app-vite 3.3.0.

CWE CWE-732
Vendor quasarframework
Product quasar
Published Oct 6, 2026
Last Updated Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for quasarframework quasar

Be the first to know when new unknown vulnerabilities affecting quasarframework quasar are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

quasarframework / quasar
< 2.23.3
@quasar / app-vite
< 3.3.0
@quasar / cli
< 5.0.4
@quasar / ssl-certificate
< 2.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/quasarframework/quasar/security/advisories/GHSA-fh39-c73x-5pjv github.com: https://github.com/quasarframework/quasar/commit/b719460aa78e88714b8a1b7ca68267234d217575 github.com: https://github.com/quasarframework/quasar/releases/tag/@quasar/app-vite-v3.3.0 github.com: https://github.com/quasarframework/quasar/releases/tag/@quasar/cli-v5.0.4